GDPR
Last updated: 2026-07-08
PayMig AB is built to comply with the EU General Data Protection Regulation (GDPR). This page summarises how we handle data protection and how you exercise your rights.
1. Our data protection principles
- Lawfulness and transparency: we process data on a clear legal basis.
- Data minimisation: we only collect what is needed.
- Privacy by design: security and privacy are part of our design, including BankID verification and encryption.
2. Data subject rights
Under the GDPR you have the right to: access your data, request rectification, request erasure ("right to be forgotten"), request restriction, object to processing, and request data portability. In the app you can export your data.
3. How to request or delete your data
Send a request to info@paymig.tech. We normally respond within 30 days. We may need to verify your identity before processing the request.
4. Data processors
We use processors such as Supabase (storage, EU region) and our email provider (SMTP) for outgoing email. Payment and identification are handled via Swish and BankID. All are bound by data processing agreements.
5. Data breaches
In the event of a personal data breach that poses a risk to your rights, we notify the Swedish Authority for Privacy Protection (IMY) within 72 hours and inform affected individuals where required.
6. Supervisory authority
You have the right to lodge a complaint with the Swedish Authority for Privacy Protection (IMY), imy.se.
7. Data protection contact
Contact us on data protection matters at info@paymig.tech.